Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2010-1365
SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2010-2335
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RIESGO
abrir
Referência
CVE-2017-15806
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s
28RIESGO
abrir
Referência
CVE-2010-4925
SQL injection vulnerability in clic.php in the Partenaires module 1.5 for Nuked-Klan allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2009-4673
SQL injection vulnerability in profile.php in Mole Group Adult Portal Script allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Active PHP BookMarks 1.1.02 - SQL Injection
CVE-2008-3748webappsphp
SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Active Force Matrix 2 - Authentication Bypass
CVE-2008-5634webappsasp
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2009-4477
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2009-3967
SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
MyioSoft Ajax Portal 3.0 - Authentication Bypass
CVE-2008-5653webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Ktools Photostore 3.5.1 - 'gid' SQL Injection
CVE-2008-6647webappsphp
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Tiger Dms - Authentication Bypass
CVE-2009-1503webappsphp
Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
MaxCMS 2.0 - 'm_username' Arbitrary Create Admin
CVE-2009-1818webappsphp
SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Frontis 3.9.01.24 - 'source_class' SQL Injection
CVE-2009-2013webappsphp
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2010-3026
Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
CVE-2006-6203webappsphp
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RIESGO
abrir
Referência
CVE-2008-5638
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2023-28285
Microsoft Office Remote Code Execution Vulnerability
41RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0839webappsphp
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
PHPhotoalbum 0.5 - Multiple SQL Injections
CVE-2008-2501webappsphp
Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2017-16928
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RIESGO
abrir
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RIESGO
abrir
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RIESGO
abrir
ReferênciaVexDay Proof
plx Ad Trader 3.2 - 'adid' SQL Injection
CVE-2008-3025webappsphp
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2009-4617
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attacker
23RIESGO
abrir
Referência
CVE-2017-15959
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-200
23RIESGO
abrir
Referência
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RIESGO
abrir
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RIESGO
abrir
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RIESGO
abrir
ReferênciaVexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
CVE-2008-3352webappsphp
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
anteriorpágina 433 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.